Live data from Hacker News

230, or not 230? That is the EARN IT question

signal.org

111–120 of 178 posts

Re: 230, or not 230? That is the EARN IT question

#111
post #107

Earlier quoted context omitted.

> No, and they wouldn't be by any informed understanding of the law. You are misinformed about the history of 230. 230 was proposed exactly because the law was interpreted the way you're saying it wouldn't be. From Wikipedia below, added emphasis mine: > This concern was raised by legal challenges against CompuServe and Prodigy, early service providers at this time. CompuServe stated they would not attempt to regulat…

So this is the thing that is really confusing me: isn't Signal like CompuServe? Signal doesn't moderate my content and in fact can't; so why would a repeal of Section 230 matter to Signal? And like, yes: maybe the people at Signal personally care... but that's not how this article is written. I feel like most of the people who are super knee-jerk pro-230 are ignoring this precedent you have pointed to of CompuServe:…

I think so, at least in theory. In practice, I suspect that would eventually get challenged in court. But (IANAL), I also suspect that you're right, and a platform like Signal would fall under the same category as CompuServe and could make a strong argument for itself using that case.

Here's where it gets tricky though -- Signal is kind of an anomaly, and there are a lot of platforms being built that both moderate content and incorporate E2E encryption. Matrix is the prime example, but even non-obvious platforms like Mastodon are talking about e2e encryption for DMs. To get a really good fediverse rolling, or even just to encourage platforms like Facebook to start using more zero-knowledge encryption, we need the ability to use E2E encryption alongside moderated content.

Pure distribution platforms are rarer than people think. I'm not particularly worried that ending Section 230 will be a disaster for private, closed, encrypted channels. But most of the best parts of the Internet happen in public channels and semi-open communities, and getting rid of 230 would have a really big negative impact on the general discourse within those communities and the freedom of like-minded people to get together and form communities online without a fear of lawsuits.

That being said, I think Signal does itself something of a disservice by not strongly asserting it's a pure distribution channel. They could talk about how this is dangerous for encryption overall while still advocating that the law wouldn't apply to someone in their position. We can simultaneously say that repealing Section 230 would be really bad for online communities, but not existentially bad for closed communication channels like Signal.

And purely from a strategic point of view, we should be interested in saying things like that, because if Section 230 does get repealed it would be very nice to have a fallback position that's already been articulated and made clear to Congress and general audiences, and that preserves at least some encryption.

But, Signal has their own set of real lawyers, so it may be that they disagree that CompuServe would apply, or it may be that they think that Congress would just keep challenging them until it found some attack that worked, or it may just be that they think aligning themselves alongside Open platforms like Matrix is more valuable than making a case that they would be exempt. I'm not going to pretend to know what's going through their minds.

Re: 230, or not 230? That is the EARN IT question

#112
post #76
post #69

Earlier quoted context omitted.

With Telegram at least, you do not have to share your contacts with the app. You can build up a Telegram-specific list of contacts based on who you message on the platform.

This is the inverse of the issue. I don't want everyone that has my phone number to be able to see/add me on telegram. That would require those users not to upload their contacts, which is out of my control.

Everyone can't. You can adjust the privacy settings such that you have to add someone to your Telegram contacts before they can discover you are on Telegram. It's easily done in Telegram's privacy settings. This is a primary reason I prefer it to signal despite the screeching from armchair crypto experts on HN anytime Telegram is mentioned.

Re: 230, or not 230? That is the EARN IT question

#113
post #60

Plenty of people have complex opinions about 230, but it's a law that says, if you see a comment that defames you, sue the person who made it, it's got nothing to do with e.g. whoever runs the skateboarding forum. Who opposes this? It's just codifying the common sense understanding of the internet.

In legal terms, Internet, especially commercial Internet is exceptional because of it is young and has unprecedented reach. Previously you could sue a paper for what they printed as it was thought obvious they will read and agree with whatever they print. And there was nothing compared to the Internet now.

Re: 230, or not 230? That is the EARN IT question

#114

Earlier quoted context omitted.

> How would a messaging app work without contact discovery? "Hey, add me on telegram, my username is @andrewzah". This isn't a hard problem. I don't know why we decided apps hoovering up our contact lists in exchange for convenience was so important. For an app that touts itself as private and secure, I still had to explain to my brother why giving it his contact list wasn't a good idea.

This is a hard problem. The evidence for this is the decades of failed attempts to get people to use pgp and other systems where I need to have a freaking party in order to figure out who I can message and how before I actually start communicating.

I would argue that's a failure of pgp, not sharing in general. People have less resistance to easy to use apps like whatsapp, riot, etc versus something like pgp.

Re: 230, or not 230? That is the EARN IT question

#115

I thought it was interesting when Twitch partners started talking about a Twitch policy that seems to hold the partner responsible for moderating their own chat. That is, if you are a partner and you have community members posting prohibited content into your Twitch chat then you stand to pay the penalty through a ban or losing your partnership. You are forced to moderate your own chat thereby relieving Twitch of hav…

Indeed. The problem with imposing liability on moderators is that they're already doing about as well as they reasonably can at a job that isn't easy. Nobody wants a platform full of spam and disinformation. But it's inherently a difficult trade off between heavy-handed censorship that catches too many dolphins in the shark net vs. not catching strictly 100% of the bad stuff. If you start imposing liability on the mo…

I think it's simple. The US postal service uses postal inspectors to try and identify packages containing narcotics[0], and yet we don't make them liable for the packages they miss. Any attempt to moderate undesirable content on a website should not then make you liable for the content you miss.

[0]: https://www.uspis.gov/about/what-we-do/

Re: 230, or not 230? That is the EARN IT question

#116

Earlier quoted context omitted.

The moment someone points out Google makes a huge amount of money on scams and malware, and due to Section 230, can't really be held responsible for it.

Fining Google doesn't help the problem there, you would want to work with Google to find out who made the deceptive ad and deal with them so they can't continue on to hurt more people

Google knows who they are: They're business partners.

Re: 230, or not 230? That is the EARN IT question

#117
post #74
post #18

Earlier quoted context omitted.

But it means they have slurped all your contacts. How are they stored? Who are they shared with? etc

The DO NOT slurp your contacts. They invented a way to do contact discovery in a secure way: https://signal.org/blog/private-contact-discovery/ . From the article: "Using this service, Signal clients will be able to efficiently and scalably determine whether the contacts in their address book are Signal users without revealing the contacts in their address book to the Signal service." This is why Signal gets so much…

> They invented a way to do contact discovery in a secure way:

Their solution is to run contact discovery on a DRM Secure Enclave system. Ironic that their privacy solution is to use a technology that privacy advocates say is the spawn of Satan because it hands over control of your machine to Intel.

Re: 230, or not 230? That is the EARN IT question

#118

Earlier quoted context omitted.

Indeed. The problem with imposing liability on moderators is that they're already doing about as well as they reasonably can at a job that isn't easy. Nobody wants a platform full of spam and disinformation. But it's inherently a difficult trade off between heavy-handed censorship that catches too many dolphins in the shark net vs. not catching strictly 100% of the bad stuff. If you start imposing liability on the mo…

I think it's simple. The US postal service uses postal inspectors to try and identify packages containing narcotics[0], and yet we don't make them liable for the packages they miss. Any attempt to moderate undesirable content on a website should not then make you liable for the content you miss. [0]: https://www.uspis.gov/about/what-we-do/

> I think it's simple. The US postal service uses postal inspectors to try and identify packages containing narcotics[0], and yet we don't make them liable for the packages they miss. Any attempt to moderate undesirable content on a website should not then make you liable for the content you miss.

> [0]: https://www.uspis.gov/about/what-we-do/

Then what about sites that would use this to their advantage and half ass the whole thing? (fwiw I'm with you, just entertaining the argument)

How do you differentiate between ignorance and malice in response? I guess via emails and memos that would come up in discovery?

Re: 230, or not 230? That is the EARN IT question

#119
post #104

Earlier quoted context omitted.

Telegram does the same thing. In fact, so does Instagram, which I find most egregious, since it asks for your number for 2FA purposes then notifies anyone who has your number saved that you’ve joined. Every coach, recruiter, drug dealer or one night stand I’ve had in my life doesn’t need to know when I sign up to Instagram. Some of them might not have even had my real name until they got that notification. IMO this s…

I think the issue here is that Instagram has a different idea of the importance of a phone number than you do. They consider a phone number to be more personal information than your full name. Your phone number is also trivially tied to your full name anyway, unless you paid for a burner phone in cash wearing a ski mask.

> trivially tied to your full name

For a government perhaps, but not your average person. This is similar to claiming that my ISP provided IP address is trivially tied to my full name because someone could subpoena it.

Re: 230, or not 230? That is the EARN IT question

#120
post #70

Earlier quoted context omitted.

Sue John Doe, and ask the court to issue a subpoena to the forum for identifying information, and then to the ISP, and once you have that, add the account holder as a defendant to the suit. It's not fast, and it's not easy, but such is life.

I'm really coming more from the perspective of valuing anonymity. I'd prefer a world where you simply can't sue the guy, and have to suck it up that people say things you don't like.

[deleted]
Post reply on HN